Vulnerabilities
Summary — last 7 days
New vulnerabilities2,765▼ 50 vs. last week
Critical / high1,432▲ 200 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)95▼ 405 vs. last week
5 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (6.1) | 0.60% | — | Actionpack Project ActionpackRubyonrails Rails | 2/9/2023 | 6/17/2026 | An open redirect vulnerability is fixed in Rails 7.0.4.1 with the new protection against open redirects from calling redirect_to with untrusted user input. In prior versions the developer was fully responsible for only providing trusted input. However the check introduced could allow an attacker to bypass with a… | |
| Modified | Medium (6.1) | 1.6% | — | Rubyonrails ActionpackDebian Linux | 5/26/2022 | 6/17/2026 | A XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 which would allow an attacker to inject content if able to control input into specific attributes. | |
| Modified | Medium (6.1) | 1.8% | — | Rubyonrails ActionpackDebian Linux | 5/26/2022 | 6/17/2026 | An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses. | |
| Modified | High (7.5) | 4.1% | — | Rubyonrails RailsRubyonrails Actionpack Page-cachingDebian Linux | 5/27/2021 | 6/17/2026 | A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input. | |
| Modified | Critical (9.8) | 5.4% | — | Rubyonrails Actionpack Page-cachingDebian Linux | 5/12/2020 | 6/17/2026 | There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote code execution if the attacker can write unescaped ERB to a view. |